fix(cve): CVE-2026-75143 - avformat/librist: honor the caller buffer size in librist_read - #43
Conversation
…size in librist_read CVE: CVE-2026-75143 (critical) - librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination. Clamp the copy to the caller-provided buffer size. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
|
/hold |
|
TAG Bot TAG: 7%6.1.5-0deepin9 |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
…to avoid heap disclosure CVE: CVE-2026-66038 (high) - avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…m underflow the packet size CVE: CVE-2026-65704 (high) - FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2026-65704 - 兼容性适配修改:添加 libavutil/macros.h 头文件以提供 FFMIN 宏定义 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…der than the plane CVE: CVE-2026-70632 (high) - cfhd 解码器中拒绝 transform-2 输出宽度大于平面的情况,修复数组越界访问 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…nt index CVE: CVE-2026-75146 (high) - FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound, allowing negative indices to access invalid memory. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…fore reallocating on size chan CVE: CVE-2026-65703 (high) - tdsc 解码器数组越界访问漏洞 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…t overflow the system header CVE: CVE-2026-75142 (high) - mpegenc: reject stream counts that overflow the system header Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1,https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f0d21ba684446fd59b49e00f3f8e9ed954df Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…ffer for the widest plane CVE: CVE-2026-65706 (high) - avfilter/vf_swaprect: size the temp row buffer for the widest plane - out of array access Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…ow in the capacity check CVE: CVE-2026-70628 (high) - dvbsub_parser 中容量检查的有符号整数溢出漏洞 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
… overflow the 16-bit count CVE: CVE-2026-75141 (high) - 整数溢出导致数组越界访问 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…arger than the RTP payload buf CVE: CVE-2026-75144 (high) - rtpenc_vc2hq: reject data units larger than the RTP payload buffer Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…aller than their header CVE: CVE-2026-64834 (high) - FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…d bound the stream count CVE: CVE-2026-64830 (high) - 堆缓冲区溢出漏洞在 vobsub 字幕处理中 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…r than the strip CVE: CVE-2026-70631 (medium) - avcodec/tiff: reject inflate output shorter than the strip - use of uninitialized memory Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…ta when the input is too short CVE: CVE-2026-70629 (medium) - 修复 rscc 解码器中的堆溢出写入漏洞 Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2026-70629 - 兼容性适配修改:无额外兼容性问题,直接应用 CVE 修复补丁 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…can_seek_to_key_sample() CVE: CVE-2026-13858 (medium) - Fix negative index given to can_seek_to_key_sample() Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de5175ae82c93edfcb2.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2026-66040 (high) - fix overrun caused by exif size discrepancy The overrun that upstream b506fafec9 hardens lives in the eXIf chunk writer of libavcodec/pngenc.c, which sizes the chunk from ff_exif_get_buffer() with AV_EXIF_TIFF_HEADER. Neither the helper nor AV_FRAME_DATA_EXIF exists in FFmpeg 6.1.5 - pngenc.c in this package never writes an eXIf chunk at all, EXIF output support was added after the 6.1 branch. The patch generated for this CVE therefore cannot be applied here: it referenced APIs that do not exist and broke the build with "implicit declaration of function 'ff_exif_get_buffer'" and "'AV_EXIF_TIFF_HEADER' undeclared". No patch required; recorded for the security tracker. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
The x86_64 FATE run fails for fate-vsynth1/2/3-ffv1-2pass, ffv1-v3-yuv422p10, ffv1-v3-yuv444p16 and ffv1-v3-rgb48. debian/rules builds with --toolchain=hardened, which makes configure add -fstack-protector-all. Together with -O3 this makes gcc (12 and 13 alike) miscompile the branchy form of renorm_encoder() that libavcodec/rangecoder.h still carries on the 6.1 branch, so the FFV1 range coder writes a corrupt extradata: the pass-1 stream is byte identical except that the FFV1 extradata grows from 190 to 298 bytes and the decoder rejects it with "quant_table_index out of range". aarch64 is unaffected because it does not get -fstack-protector-all here. Backport upstream b2da4c33e31f85b9c755f2cdb08f5db694e90ca9, which rewrites renorm_encoder() without the c->outstanding_byte < 0 shortcut. The generated bitstream is unchanged: the reference hashes are identical with and without -fstack-protector-all. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b2da4c33e31f85b9c755f2cdb08f5db694e90ca9 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
|
PR #44 has been merged into this branch ( Merged in (cherry-picked, branch stays linear for CVE-2026-66040 is recorded as Also fixed here: the pre-existing x86_64 FATE failure. Before this update, Backported upstream Verified on this branch: 27 patches apply cleanly, build clean, full FATE |
…iables CVE: CVE-2026-65705 (high) - FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
1. CVE-2026-65704: fix Origin field from N/A to upstream commit URL (de771bd), update Description to proper security fix description explaining the 6.1.5 backport adaptation (FFMIN macro header). 2. CVE-2026-70629: fix Origin field from N/A to upstream commit URL (cd1f545), align with changelog reference. 3. CVE-2026-13858: add runtime guard (if (sample < 0) return 1) before av_assert0 so a negative index returns a safe default instead of crashing, providing defense-in-depth beyond the always-on av_assert0.
|
/integrate |
|
AutoIntegrationPr Bot |
CVE: CVE-2026-75143 (critical) - librist_read() ignored its size argument and copied the full payload_len, overflowing a smaller destination. Clamp the copy to the caller-provided buffer size.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602.patch
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-66038 (high) - avcodec/lcldec: zero the not-decoded tail to avoid heap disclosure
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c.patch
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-65704 - 兼容性适配修改:添加 libavutil/macros.h 头文件以提供 FFMIN 宏定义
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-70632 (high) - cfhd 解码器中拒绝 transform-2 输出宽度大于平面的情况,修复数组越界访问
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9.patch
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-75146 (high) - FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound, allowing negative indices to access invalid memory.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-65703 (high) - tdsc 解码器数组越界访问漏洞
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-65705 (high) - FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0.
Upstream: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b